PT-2018-8501 · Netiq · Netiq Identity Manager
Published
2018-03-02
·
Updated
2019-10-09
·
CVE-2017-9279
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
NetIQ Identity Manager versions prior to 4.5.6.1
Description
The issue allows malicious user administrators to upload files with double extensions or non-image content in the Themes handling of the User Application Administration. This could potentially lead to code execution or misleading users.
Recommendations
For versions prior to 4.5.6.1, update to version 4.5.6.1 or later to resolve the issue. As a temporary workaround, consider restricting file uploads in the User Application Administration to minimize the risk of exploitation.
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netiq Identity Manager